Malware not letting me Format the Windows drive.

wealstarr

New Member
Thread author
Nov 26, 2016
2
Hello,
It was 2 days ago. The USB that I got the infection from had a shortcut and all the data was inside that shortcut. I pulled it out and plugged in my USB and I noticed that the shortcut was made and all the data was copied in it. I went to the task manager to see the running processes and found msinstaller.msi running. Startup had one more entry added to it, in which there was some file and masiinstaller listed. I disbaled them from starting up with the windows, browsed the file located in the user folder's appdata with winrar and deleted it. (I was connected to the internet and I presume something was installed on my machine)

I noticed that my folder options have been changed from "show hidden files" to "do not show hidden files"

I tried to do a clean install. When I tried to boot fromthe USB, there was no option during the start up to boot from external device. I went to the bios options and changed the boot device order. Then I tried again and I saw the option to boot from the USB , when I tried it the point where the first screen shows it took a long pause and then booted from the harddrive. Tried it several times with no success.

I also tried to do system restore but it couldn't complete giving error that it can't access the necessary files.
I scanned the boot sectors and entire system with Avira free and zonealarm trial version but they couldn't detect anything. I think the malware had installed some genuine addon to bypass the boot from external drives.

Lastly, with winrar I see a lot's of files in my user account that weren't there before. Here are the screenshots-
http://i.imgur.com/UNz7Ms7.jpg
http://i.imgur.com/O5qefqX.jpg

The malware has changed a lot of things into the registry.

I just want to do a clean install from USB. I don't have any files to back up on the windows partition.

Any help will be greatly appreciated. Awaiting reply
 

Attachments

  • FRST.txt
    92.3 KB · Views: 2
  • Addition.txt
    13.8 KB · Views: 1

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,

Previous posts were deleted.

Your computer isn't infected and there is no malware that can block you from reinstalling your system. You probably did something wrong, either your USB isn't bootable or you didn't set the options correctly.
 

wealstarr

New Member
Thread author
Nov 26, 2016
2
Thanks for the reaction TwinHeadedEagle

Yeah it's definitely infected. I can't do a system restore either, nothing that can delete the malware. A friend of mine had the same problem a few months back when he got infected with the same USB.

Also, nothing wrong with my settings. Formatted it like hundred of times with the same USB and same settings.

Is it possible to destroy the installed windows in some way that it becomes unbootable at least so that I can continue installing a fresh copy?
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
If your USB is infected you can disinfect it with this tool. I will repeat, there is no infection on your system and there is no way malware can block you from installing your operating system. Either you don't know what you are doing or your bootable USB isn't configured properly or is infected.

Please download MCShield from one of the following links:

MCShield -Official download link
  • Double click on MCShield-Setup to install the application.
    Next => I Agree => Next => Install ... per installation click on Run! button.
  • Wait a few seconds to MCShield finish initial HDD scan...
  • Connect all your USB storage devices to the computer one at a time. Scanning will be done automatically.
  • When all scanning is done, you need to post a logreport that MCShield has created.
Under Logs tab (in Control Center) for AllScans.txt log section click on Save button. AllScanst.txt report shall be located on your Desktop.

=> Post here AllScanst.txt


Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top